Cybersecurity News, Awards, Webinars, eSummits, Research SC Media

cybersecurity news

Most organizations have incident response plans, security tools, and technical teams in place. The technique requires code execution in the victim’s signed-in session. “We have implemented universal monitoring for risky actions and misalignment across all agentic applications of Astra, including training and evaluation. Monitors evaluate the model’s Chain of Thought and trigger a security re… OpenAI has announced that it’s pausing some “internal activities” involving its upcoming artificial intelligence (AI) model Astra after an internal evaluation found it had made significant advancements in agentic coding and cybersecurity.

NVIDIA and 36 other organizations have formed the Open Secure AI Alliance to develop and share open technologies, techniques, and tools for securing software and artificial intelligence (AI) agents. The Computer Emergency Response Team of Ukraine (CERT-UA) has disclosed details of a new social engineering campaign orchestrated by Russian nation-state threat actors targeting IT workers in the country by masquerading as recruiters to trick them into installing malware. In this report experts explain how AI cybersecurity agents can help them secure their businesses A newly identified threat actor is running a large-scale, long-running cyber campaign targeting Salesforce Experience Cloud sites and ServiceNow Service Portals globally.

Entra ID researcher Dirk-jan Mollema demonstrated that malware already running in a signed-in Windows session can silently use the victim’s Windows Hello for Business key to authenticate to Microsoft Entra ID. But security teams still have to review vulnerabilities, manage dependencies, prioritize fixes, and control risk at human speed. Microsoft says a new Defender capability isolated a compromised device and stopped a ransomware attack in 128 seconds. Carlos Morales, SVP & General Manager of Arbor Cloud, NETSCOUT says how proactive defences for uninterrupted availability is now a business risk imperative…

If teams can suddenly create many times more code, security can also end up with many more components, dependencies, findings, and fixes to manage. In our latest webinar with Chainguard experts, “ The True Cost of Building at Machine Speed ,” you can now watch how security teams can keep AI-driven development fast without letting risk scale with it. GPT-5.6-Cyber, a more cyber-permissive version of GPT-5.6 Sol, builds upon GPT‑5.5‑Cyber , which OpenAI released in June 2026. The artificial intelligence (AI) company said it’s making GPT 5.6 Cyber available through Daybreak Red, a new tier that provides access to its purpose-trained cybersecurity models to other firms for authorized vulnerability research, exploit validation, and security testing. “Built on GPT‑5.6 Sol, it is trained to improve capabilities on several specialized cybersecurity tasks (e.g., finding zero-day vulnerabilities and developing exploit chains) and to reduce refusals for certain higher-risk, dual-use cyber tasks,” OpenAI said .

AI “Mind Viruses” Can Spread Between Agents Through Persistent Prompt Files

cybersecurity news

In this video interview, Standard Chartered’s group CISO shares insights on transitioning from technical roles to strategic leadership, the importance of business-savvy security executives, and how AI is reshaping both defensive capabilities and adversarial tactics in banking. As part of Dark Reading’s 20th anniversary celebration, we trace the industry’s evolution through a technology lens. As part of Dark Reading’s 20th anniversary special coverage, we profile the CISOs, founders, researchers, criminals, and policymakers who rewrote the enterprise risk playbook. The botnet adds exploitation modules, credential theft, and reverse SOCKS relays to turn compromised devices into persistent attacker infrastructure. Join this live webinar as we explore if detection-first security operations can keep pace with AI, or if it’s time to rethink prevention as the strongest default. Identity confidence changes throughout every interaction and should be reassessed continuously as new risk signals emerge.

Gunra Ransomware Builds a New Attack Network Through RaaS

  • The program could allow vetted private US companies to access targeted systems without the owner’s authorization and, in more disruptive operations, damage or destroy systems or infrastructure.
  • Microsoft’s August 2026 Patch Tuesday fixes roughly 400 flaws, including three Zero-days, with one actively exploited and two publicly disclosed.
  • In this report experts explain how AI cybersecurity agents can help them secure their businesses
  • This week’s roundup examines corporate cyberattacks, AI security risks, Microsoft zero-days, logistics disruption and threats targeting personal accounts.
  • This prolific information-stealing malware quietly strips compromised systems of saved browser passwords, payment card details, and cryptocurrency wallets in a single execution.
  • The Police National Legal Database (PNLD) has confirmed that police, government and customer contact information was compromised and published on the dark web.

This technological shift enables threat actors… OpenAI has warned that advancing artificial intelligence models are increasingly capable of automating critical phases of real-world cyberattacks.

cybersecurity news

From Bobmojis to Bobbleheads: How the Democratic Party Built a Security-First Culture

Chester – known as Chet – opens up about putting out the fire of cybercrime with AI and agents that hand today’s defenders a frontier AI advantage… Huntress documents how a ransomware affiliate sabotaged its own attack with an anti-EDR effort GBHackers on Security is a top cybersecurity news platform, delivering up-to-date coverage on breaches, emerging threats, malware, vulnerabilities, and global cyber incidents. North Korean state-backed threat actor Kimsuky is extending its established espionage playbook with locally hosted artificial intelligence tooling, according to new research into an… Protect your business against the most common cyber threats with Cyber Essentials. It is worrying if you are victim of an online scam or cyber attack.

GitHub on Wednesday officially confirmed that the breach of its internal repositories was the result of a compromise of an employee device involving a poisoned version of the Nx Console Microsoft Visual Studio Code (VS Code) extension. Google’s Mandiant attributes it to the group it tracks as UNC6240, and dates the activity between May 27 and June 9. “Salesforce took this action because our security teams recently detected unusual activity involving the app that may have resulted in unauthorized access to a subset of customer data via the app’s connection to Salesforce,” it noted . Krishnan does not name the victim, but the chat points to Union County, Ohio. It also worked with Salesforce to roll out new detection and governance tooling aimed at addressing the activity authentication logs miss.

In research published July 13 , Microsoft mapped the campaigns, which ran from mid-2025 into mid-2026, to three distinct techniques. The charge was Section 3ZA of the Computer Misuse Act 1990, the Act’s most serious, and they admitted https://power-at-work.com/cybersecurity-risks-and-solutions-for-connected-construction-equipment/ it on the basis that they were reckless as to whether they caused or created a significant risk of serious damage to human welfare. Armenia has held a Russian tourist named Aleksandr Ermakov in a detention center since June 28, on a U.S. extradition request for a REvil ransomware suspect named Aleksandr Ermakov. The company said it detected and responded to the incident targeting its production infrastructure earlier last week.

McDonald’s, Vodafone Hit by Azure Credential Theft Campaign Exposing Millions of Enterprise Records

The ransomware group known as DeadLock has been observed using decentralized infrastructure to facilitate victim communications and https://www.inrecognition.org/what-impact-does-cybersecurity-have-on-business-trust/ data leak operations in a bid to improve operational resilience. Users running self-hosted versions are advised to apply security patches released b… Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. “GitLab.com and GitLab Dedicated are already running the patched version. GitLab.com and GitLab Dedicated customers do not need to take action,” the company said. A cryptocurrency fraud operation has been found using AI coding tools to turn huge phone lists into a sharper victim-targeting system.

cybersecurity news

No evidence of data breach after Chinese-made component found in Navy drones, MoD says

A federal judge in Alexandria, Virginia, sentenced Maksim Silnikau to 16 years in prison on August 5 for creating and running Ransom Cartel , the ransomware-as-a-service operation he stood up in 2021. The tech giant said it observed the ransomware being deployed by multiple threat actors, including an affiliate for Lynx and INC ransomware. Grafana Labs, on May 19, 2026, said an investigation into its recent breach found no evidence of customer production systems or operations being compromised. In an ironic twist, open-source artificial intelligence (AI) platform Hugging Face revealed that it was the victim of a hack perpetrated by an autonomous AI agent system. Threat actors linked to the Cl0p (aka Chubby Scorpius, FIN11, Graceful Spider, and Lace Tempest) ransomware campaign are exploiting flaws in internet-exposed PTC Windmill and FlexPLM deployments as part of a new data extortion campaign. JFrog says it has since developed and released fixes for cloud and self-hosted customers.

  • Apple on Thursday sent a fresh batch of notifications to customers whom it suspects may have been targeted by mercenary spyware attacks.
  • A Powerful, All-in-One Solution for Cyber-Resilient Backup and Recovery In an era where ransomware, cloud complexity, and regulatory pressures are reshaping data protection priorities, NAKIVO Backup & Replication v11 provides…
  • In this video interview, Standard Chartered’s group CISO shares insights on transitioning from technical roles to strategic leadership, the importance of business-savvy security executives, and how AI is reshaping both defensive capabilities and adversarial tactics in banking.
  • Reddit is increasing its use of moderation tools and getting rid of Automod, and many moderators aren’t happy at all.
  • OpenSourceMalware, which discovered the activity on August 15, 2026, is tracking the threat under the moniker StubMaker .

Metabase Cloud instances have already been updated to the latest version. Metabase has warned that a maximum-severity security flaw impacting its business intelligence and data visualization software package has been exploited in the wild as a zero-day. Hackers deploy AI agents to breach Taiwanese government systems. Data-theft campaign targets misconfigured Salesforce and ServiceNow instances.

Leave a Reply

Your email address will not be published. Required fields are marked *